← Zuruck zu CVEs
CVE-2021-31930
MEDIUM6.1
Beschreibung
Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.
CVE Details
CVSS v3.1 Bewertung6.1
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht5/19/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
concerto-signage:concerto
Schwachen (CWE)
CWE-79
Referenzen
https://github.com/concerto/concerto/pull/1558(cve@mitre.org)
https://github.com/concerto/concerto/security/advisories(cve@mitre.org)
https://github.com/concerto/concerto/pull/1558(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/concerto/concerto/security/advisories(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.